Search our Spoof Library...
Another Spoof Email and Phishing Scam report by MillerSmiles.co.uk - click this image to go to our home page.

eBay - Security Measures (SafeHarbor) (KMM82003618V76837L0KM)
24th May 2004

please forward any scams you've received to spoof@millersmiles.co.uk

 

Report Summary
Date Reported
first reported 28th March 2004
Apparent Sender
eBay
Return Address
CustomerSupport@eBay.com
Subject
Security Measures (SafeHarbor) (KMM82003618V76837L0KM)
Format
HTML
Method
disguised link leads to bogus web content
Bogus Web Content?
Yes
URL of web content
http://211.23.103.36/... (28/03/04) - resolves to Taiwanese web space in Taiwan.
and
http://www.c4.ca/pass/signin.php?..... (10/05/04) - resolves to Canadian web space.
and http://www.secureebaypayonline.us/signin.php - resolves to a Yahoo user's web space.
and http://61.8.215.38/.aw-cgi/eBayISAPI.php - resolves to web space in Singapore
RISK LEVEL
Medium
WARNINGS

1. Note the URL of the bogus page.

 

" Dear eBay member, We recently noticed one or more attempts to log in to your eBay account from a foreign IP address "...

 

This spoof eBay email (see image below) is in HTML format (although it does look like a text only email in order add a sense of authenticity to the link text). The link in the email has been disguised using HTML code to look like a genuine link to eBay but it will lead you to a bogus eBay web form (see image below).

Any information submitted is processed through a script located on the same server as the bogus content.

If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.

 

The Spoof Email ...

Dear eBay member

We recently noticed one or more attempts to log in to your eBay account from a foreign IP address and we have reasons to belive that your account was hijacked by a third party without your authorization.

If you recently accessed your account while traveling,the unusual log in attempts may have been initiated by you.
However,if you are the rightfull holder of the account, click on the link below, fill the form and then submit as we try to verify your identity.

http://cgi3.ebay.com//aw-cgi/eBayISAPI.dll?VerifyIdentity&ssPageName=
;
The log in attempt was made from:
IP address: 205.188.209.166
ISP host: cache-dq04.proxy.aol.com

If you choose to ignore our request,you leave us no choise but to temporaly suspend your account.

We ask that you allow at least 72 hours for the case to be investigated and we strongly recommend not to make any changes to your account in that time.

If you received this notice and you are not the authorized account
holder, please be aware that it is in violation of eBay policy to represent oneself as another eBay user. Such action may also be in violation of local, national, and/or international law. eBay is committed to assist law enforcement with any inquires related to attempts to misappropriate personal information with the intent to commit fraud or theft. Information will be provided at the request of law enforcement agencies to ensure that perpetrators are prosecuted to the fullest extent of the law.

*Please do not respond to this e-mail as your reply will not be received.

Thanks for your patience as we work together to protect your account.

Regards,

Safeharbor Department
eBay Inc

 

The bogus web page ...

eBay - Security Measures (SafeHarbor) (KMM82003618V76837L0KM) spoofed email

 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...
 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...

Email Alerts
Add your email address to our email alert service...
Subscribe

Privacy Policy

RSS News Feed
Tap into our Scam Alert service using your News Reader or Aggregator (including My Yahoo!).
Scam Alert News Feed

You can even put the latest alerts on your own web site.

Click here to learn more about RSS News Feeds and our Scam Alert Service!

Resources links - use one of the links below to access more information on Spoof Email & Phishing Scams.

Library of Spoof Email Phishing Scams

Brief guide to Phishing

Full article on spoof email scams

Spoof URL Checker

Link Checker

Browser URL Spoofing Vulnerability Check

Latest browser bug aids Phishing Scams - beware!

Destinations - other resources available on the MillerSmiles.co.uk web site.

Click the arrow to return to previous page

Home

Guides...

Book Terminology

How to identify a first edition book

Auction Watcher

List of the main Auction Sites world wide